Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Slackware 8.1: Samba 2.2.7 Moderate Security Update for Buffer Overflow

slackware
Calendar Grey November 22, 2002
Dist Slackware Esm H88
Samba packages intended for Slackware iterations 8.1 and -current possess significant buffer overflow weaknesses, potentially granting attackers unapproved root access.
New Samba packages are available for Slackware 8.1 and -current to fix a security problem and provide other bugfixes and improvements.

Summary

Here are the details from the Slackware 8.1 ChangeLog: ---------------------------- Wed Nov 20 16:51:23 PST 2002 patches/packages/samba-2.2.7-i386-1.tgz: Upgraded to samba-2.2.7. Some details (based on the WHATSNEW.txt file included in samba-2.2.7): This fixes a security hole discovered in versions 2.2.2 through 2.2.6 of Samba that could potentially allow an attacker to gain root access on the target machine. The word "potentially" is used because there is no known exploit of this bug, and the Samba Team has not been able to craft one ourselves. However, the seriousness of the problem warrants this immediate 2.2.7 release. There was a bug in the length checking for encrypted password change requests from clients. A client could potentially send an encrypted password, which, when decrypted with the old hashed password could be used as a buffer overrun attack on the stack of smbd. The attack would have to be crafted such that converting a

Read the Full Advisory

Where Find New Packages

MD5 Signatures

Severity
important
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Related News

Your message here